CVE-2020-25577: Critical severity freebsd kernel vulnerability
In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 rtsold(8) does not verify that the RDNSS option does not extend past the end of the received packet before processing its contents. While the kernel currently ignores such malformed packets, it passes them to userspace programs. Any programs expecting the kernel to do validation may be vulnerable to an overflow.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25577?
CVE-2020-25577 is a vulnerability in FreeBSD operating system versions 11.4 and 12.1 that allows an attacker to execute arbitrary code by exploiting a flaw in the rtsold(8) program.
How severe is CVE-2020-25577?
CVE-2020-25577 has a severity score of 9.8 (critical) out of 10.
Which versions of FreeBSD are affected by CVE-2020-25577?
FreeBSD versions 11.4 and 12.1 are affected by CVE-2020-25577.
How do I fix CVE-2020-25577?
To fix CVE-2020-25577, it is recommended to update your FreeBSD system to the latest available patch or upgrade to a non-vulnerable version.
Where can I find more information about CVE-2020-25577?
You can find more information about CVE-2020-25577 on the FreeBSD Security Advisories website and the NetApp security advisory.